Vulnerabilities > Netiq > Imanager > 3.0.3

DATE CVE VULNERABILITY TITLE RISK
2018-03-02 CVE-2017-5189 Improper Authentication vulnerability in Netiq Imanager
NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.
network
low complexity
netiq CWE-287
7.5
2017-05-03 CVE-2017-7432 Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
network
low complexity
novell netiq
critical
9.8
2017-05-03 CVE-2017-7431 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
network
low complexity
novell netiq CWE-352
8.8
2017-05-03 CVE-2017-7430 Cross-site Scripting vulnerability in multiple products
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.
network
low complexity
novell netiq CWE-79
6.1
2017-05-03 CVE-2017-7428 Improper Input Validation vulnerability in Netiq Imanager
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.
network
low complexity
netiq CWE-20
5.3